CVE-2026-102568

Source
https://cve.org/CVERecord?id=CVE-2026-102568
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-102568.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-102568
Published
2026-09-29T14:22:37Z
Modified
2026-10-02T03:30:54Z
Severity
  • 6.8 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Pardus Parental Control before 0.7.0 Incorrect Authorization via PPCActivator.py
Details

Pardus Parental Control before 0.7.0 contains an incorrect authorization vulnerability in the polkit policy that allows unprivileged local users to disable parental controls as root. Attackers can invoke PPCActivator.py with the --disable argument via pkexec to remove all restrictions including DNS filtering and application limits without authentication.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-863"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-102568.json"
}
References

Affected packages

Git / github.com/pardus/pardus-parental-control

Affected ranges

Type
GIT
Repo
https://github.com/pardus/pardus-parental-control
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "0.7.0"
        }
    ],
    "source":  [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

debian/0.*
debian/0.3.2
debian/0.3.3
debian/0.4.1
debian/0.5.1
debian/0.6.0
debian/0.6.1
v0.*
v0.3.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-102568.json"